What this means for your organisation

  • Documents and metadata stay within your legal jurisdiction, no US provider reading along.
  • Predictable storage costs without per-user-per-month surprises.
  • One platform for files, calendars, video calls and documents, no separate subscriptions.

Overview

Sharing files, collaborating on documents, and syncing calendars do not belong on a SaaS platform whose business model is your data. We deploy and operate Nextcloud as an open-source alternative to Google Drive, OneDrive or Dropbox: the same user experience, fully under your control, and with no US provider able to look at your documents.

Our Approach

  • 100% open source: Nextcloud Hub as the platform for files, calendars, contacts, video calls (Talk), an office suite (OnlyOffice or Collabora), and project tools. No vendor lock-in, no proprietary protocols.
  • Privacy and data sovereignty: Hosting in the EU on your own servers or ours. No telemetry, no tracking, no third-party access. Documents and metadata stay inside your legal jurisdiction.
  • End-to-end encryption: Server-side encryption for data at rest, optional end-to-end encryption for sensitive folders where even the administrator cannot read the content, and TLS everywhere in transit.
  • SSO and MFA: Authentication via your existing identity provider (LDAP, Active Directory, Keycloak, OIDC) with MFA. RBAC, group folders, and sharing policies aligned with your organisational structure.
  • Scalable storage: S3-compatible backend (MinIO, Ceph) for petabyte scale, or classic storage where that fits better. Versioning, trash, and encryption at rest by default.
  • Backups and disaster recovery: Encrypted off-site backups, point-in-time restore, and regular restore drills.
  • Migration and governance: Guided migration from Microsoft 365, Google Workspace, Dropbox, or a legacy file server, with retention policy, audit logging, and compliance reporting for GDPR or ISO 27001.

Technologies

  • Core: Nextcloud Hub, Nextcloud Talk, OnlyOffice or Collabora Online
  • Storage: MinIO, Ceph, NFS, S3-compatible backends
  • Database: PostgreSQL with streaming replication and PITR
  • Authentication: LDAP, Active Directory, Keycloak, OIDC, MFA
  • Backup: Borg, Restic, Velero for the full stack
  • Monitoring: Wazuh audit logs, Prometheus, Grafana, Loki